Fortinet NSE5_FSW_AD-7.6 Practice Test Questions and Exam Dumps Part9 Q161-180

View Full Fortinet NSE5_FSW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 161

Which FortiSwitch capability allows an administrator to centrally view the operational status of multiple managed switches?

  1. Centralized monitoring
  2. DHCP relay
  3. Port mirroring
  4. MAC aging

Correct Answer: 1

Explanation:

Centralized monitoring allows administrators to view important operational information for multiple managed FortiSwitch devices from a centralized management environment. This can include device availability, interface status, alarms, configuration state, and other operational information depending on the deployment. Centralized visibility is particularly valuable when an organization has many switches distributed across different network segments or locations. DHCP relay is used to forward DHCP requests, port mirroring copies traffic for analysis, and MAC aging controls learned MAC entries. Centralized monitoring therefore provides the broadest operational visibility across managed switching infrastructure.

Question 162

What is the main purpose of a configuration backup for a FortiSwitch?

  1. To increase PoE output
  2. To preserve configuration information for recovery or restoration
  3. To replace firmware automatically
  4. To create additional Ethernet ports

Correct Answer: 2

Explanation:

A configuration backup preserves important switch settings so they can be restored if the device experiences a failure, configuration error, or other operational problem. Depending on the management architecture, configurations may also be centrally maintained or backed up through management systems. Having a reliable backup can significantly reduce recovery time because administrators do not need to rebuild the configuration manually. Configuration backups do not increase PoE capacity, replace firmware by themselves, or create additional physical ports. Regular backup procedures are therefore an important part of operational resilience and network administration.

Question 163

Which condition can cause an Ethernet interface to repeatedly go up and down?

  1. An incorrect NTP server
  2. A missing SNMP community
  3. An unstable physical connection
  4. An incorrect RADIUS accounting setting

Correct Answer: 3

Explanation:

An unstable physical connection can cause an Ethernet interface to repeatedly transition between up and down states. Possible causes include a damaged cable, faulty transceiver, loose connection, incompatible hardware, or a problem with the connected device. Administrators should examine interface event logs and operational statistics and test the physical components when troubleshooting link flapping. NTP, SNMP, and RADIUS settings generally do not directly cause a physical interface to lose and regain carrier repeatedly. Identifying the physical or Layer 1 cause is important because repeated link changes can also affect higher-level network protocols.

Question 164

What is the purpose of a switch configuration revision or change history in a centralized management environment?

  1. To provide a record of configuration changes
  2. To assign IP addresses automatically
  3. To increase interface bandwidth
  4. To supply PoE to endpoints

Correct Answer: 1

Explanation:

Configuration revision or change history helps administrators understand how a device’s configuration has changed over time. This information can be valuable when troubleshooting a problem that appeared after a configuration modification. It can also support operational accountability and make it easier to identify which settings were recently changed. Depending on the management platform, administrators may be able to compare or restore previous configuration states. IP address assignment, bandwidth increases, and PoE delivery are separate functions. Maintaining configuration history is therefore useful for controlled network administration and troubleshooting.

Question 165

Which protocol helps a switch discover directly connected network devices and their capabilities?

  1. DHCP
  2. RADIUS
  3. LLDP
  4. LACP

Correct Answer: 3

Explanation:

Link Layer Discovery Protocol, or LLDP, allows network devices to advertise information about themselves to directly connected neighbors. A switch can learn details such as the neighboring device identity, port information, and supported capabilities when LLDP is enabled and supported. This information can help administrators build topology views and troubleshoot physical connectivity. DHCP provides IP configuration, RADIUS supports centralized authentication and accounting, and LACP manages link aggregation. LLDP is therefore the protocol most directly associated with discovering neighboring network devices at the data-link layer.

Question 166

What is a key advantage of using FortiLink to manage FortiSwitch devices with FortiGate?

  1. It provides integrated management and configuration
  2. It removes the need for Ethernet connectivity
  3. It disables VLAN functionality
  4. It converts every switch port into a WAN interface

Correct Answer: 1

Explanation:

FortiLink provides an integrated management relationship between FortiGate and FortiSwitch. This allows administrators to manage switch configuration and monitor connected switching infrastructure through the FortiGate environment. Depending on the deployment, FortiLink can simplify tasks such as VLAN configuration, device authorization, interface management, and centralized visibility. It does not eliminate the physical network connection between the devices, disable VLANs, or convert switch ports into WAN interfaces. The major benefit is the integration of switching management with the broader Fortinet network-security architecture.

Question 167

Which STP protection feature can help prevent an edge port from becoming an unintended path to the root bridge?

  1. Root Guard
  2. DHCP snooping
  3. Port mirroring
  4. NTP

Correct Answer: 1

Explanation:

Root Guard is an STP protection mechanism designed to prevent an interface from accepting superior BPDUs that could cause an unexpected device to become part of the preferred root path. It is useful on ports where the administrator does not expect a downstream switch to influence the spanning-tree root topology. If an unexpected superior BPDU is received, the port can be placed into an appropriate protective state according to the implementation. DHCP snooping protects DHCP operations, port mirroring copies traffic, and NTP synchronizes time. Root Guard is therefore the appropriate STP protection feature.

Question 168

What is the primary function of DHCP relay in a routed network?

  1. To combine physical Ethernet links
  2. To forward DHCP requests between clients and a DHCP server on another network
  3. To inspect ARP packets
  4. To discover neighboring switches

Correct Answer: 2

Explanation:

DHCP relay allows DHCP client requests to reach a DHCP server located on a different Layer 3 network. Because DHCP discovery traffic is normally broadcast-based, routers do not forward it as a normal broadcast. A DHCP relay agent receives the request and forwards the necessary information toward the configured DHCP server. This allows a centralized DHCP server to serve clients across multiple subnets or VLANs. LACP handles link aggregation, DAI handles ARP inspection, and LLDP performs neighbor discovery. DHCP relay is therefore essential when DHCP services are located outside the client’s local broadcast domain.

Question 169

What should be checked if an LACP aggregate does not form between two switches?

  1. The NTP timezone
  2. The VLAN name only
  3. LACP mode and member-interface compatibility
  4. The SNMP trap destination only

Correct Answer: 3

Explanation:

When an LACP aggregate fails to form, administrators should verify that the member interfaces on both devices have compatible LACP configurations. This includes checking LACP mode, interface membership, speed and duplex compatibility, and other requirements for link aggregation. The physical links should also be operational. An incorrect or incompatible configuration on one member can prevent the logical aggregate from forming correctly. NTP, SNMP traps, and VLAN naming do not directly establish an LACP relationship. Verifying the aggregation settings on both ends is therefore an important troubleshooting step.

Question 170

Which feature can restrict a switch port so that only specific MAC addresses are permitted?

  1. Port security
  2. LLDP
  3. NTP
  4. DHCP relay

Correct Answer: 1

Explanation:

Port security can be used to control which MAC addresses are allowed to use a switch interface. This can help limit unauthorized devices from connecting through a particular port. Depending on the configuration, administrators may specify allowed MAC addresses or use dynamically learned addresses and define a maximum number of permitted addresses. This feature is particularly useful for endpoint access ports where the expected device population is known. LLDP provides discovery information, NTP synchronizes time, and DHCP relay forwards DHCP traffic across Layer 3 boundaries. Port security is therefore the correct choice.

Question 171

What is the purpose of SNMP polling in network management?

  1. To aggregate Ethernet links
  2. To periodically retrieve device information from a managed device
  3. To assign VLAN IDs
  4. To prevent ARP spoofing

Correct Answer: 2

Explanation:

SNMP polling allows a management system to periodically query network devices for operational information. Depending on the supported MIBs and configuration, the management platform can collect information such as interface statistics, device status, resource utilization, and other monitoring data. Polling provides a regular view of device health and can help identify trends or abnormal conditions. LACP aggregates links, VLAN configuration handles Layer 2 segmentation, and DAI helps protect against ARP spoofing. SNMP polling is therefore primarily a monitoring and information-collection mechanism rather than a traffic-control feature.

Question 172

What is a potential benefit of configuring BPDU Guard on ports connected only to end-user devices?

  1. It helps prevent an unauthorized switch from participating in STP through that port
  2. It increases the port’s PoE budget
  3. It creates a new management VLAN
  4. It assigns IP addresses to clients

Correct Answer: 1

Explanation:

BPDU Guard is useful on ports that should connect only to end devices. If a user connects an unauthorized switch to such a port, the new switch may begin transmitting BPDUs and attempt to participate in the spanning-tree topology. BPDU Guard provides protection by detecting unexpected BPDUs and taking the configured protective action. This reduces the possibility that an accidental or unauthorized switch connection will affect the Layer 2 topology. BPDU Guard does not assign IP addresses, create VLANs, or increase PoE capacity.

Question 173

Which setting helps ensure that voice traffic from an IP phone is placed into the intended voice VLAN?

  1. Voice VLAN configuration
  2. MAC aging
  3. NTP configuration
  4. RADIUS accounting

Correct Answer: 1

Explanation:

Voice VLAN configuration allows network administrators to place IP phone traffic into a designated VLAN separate from ordinary data traffic. This separation can simplify network management and allow different policies to be applied to voice and user data. Depending on the environment, discovery mechanisms such as LLDP-MED may assist in communicating network policy information to supported phones. MAC aging, NTP, and RADIUS accounting serve different purposes. Correct voice VLAN configuration is therefore essential when an IP phone needs to operate within a dedicated voice network.

Question 174

What is the main purpose of an STP topology change notification?

  1. To inform the spanning-tree system that the topology has changed
  2. To authenticate a user
  3. To assign a DHCP address
  4. To negotiate PoE power

Correct Answer: 1

Explanation:

An STP topology change notification informs the spanning-tree system that a relevant Layer 2 topology change has occurred. Such changes can result from events such as interfaces going up or down and may require switches to adjust their handling of learned forwarding information. Propagating topology-change information helps switches adapt to changes in the network topology. User authentication, DHCP addressing, and PoE negotiation are unrelated processes. Understanding topology changes is important when diagnosing temporary connectivity changes or unusual MAC-table behavior following link-state events.

Question 175

Which configuration can help limit unnecessary broadcast traffic entering a switch network from a problematic endpoint?

  1. NTP
  2. Storm control
  3. RADIUS accounting
  4. LLDP

Correct Answer: 2

Explanation:

Storm control can help protect a switched network from excessive broadcast, multicast, or related traffic depending on the supported configuration. A malfunctioning device, loop, or other abnormal condition can generate large amounts of Layer 2 traffic that consumes switch resources and affects other endpoints. Storm-control thresholds can limit the impact of such traffic by applying configured protective behavior when traffic exceeds the permitted level. NTP, RADIUS accounting, and LLDP perform completely different functions. Storm control is therefore an important mechanism for reducing the effect of excessive Layer 2 traffic.

Question 176

Why is firmware compatibility important when adding or replacing a FortiSwitch in a managed environment?

  1. It can affect management and feature compatibility
  2. It determines the Ethernet cable category
  3. It automatically creates every VLAN
  4. It eliminates the need for authentication

Correct Answer: 1

Explanation:

Firmware compatibility is important because the switch firmware must work properly with the management platform and other components of the Fortinet deployment. Incompatible versions can result in unsupported features, provisioning problems, unexpected behavior, or management limitations. Before upgrading or replacing a device, administrators should review supported versions and consider compatibility with the relevant FortiGate or management environment. Firmware does not determine the physical category of Ethernet cable, automatically create every VLAN, or remove authentication requirements. Compatibility planning helps ensure a stable and supported deployment.

Question 177

Which feature provides a copy of network traffic from one switch interface to another interface for analysis?

  1. DHCP relay
  2. Port mirroring
  3. Root Guard
  4. LACP

Correct Answer: 2

Explanation:

Port mirroring copies selected traffic from one or more source interfaces or traffic directions to a designated destination interface. A network administrator can connect a packet-analysis or monitoring device to the destination interface to inspect traffic without directly interrupting normal forwarding. Port mirroring is useful for troubleshooting, security analysis, and network visibility. DHCP relay forwards DHCP requests across Layer 3 networks, Root Guard protects STP topology, and LACP combines physical links. Therefore, port mirroring is the appropriate feature when traffic needs to be copied for analysis.

Question 178

What is the primary purpose of securing administrative access to a FortiSwitch?

  1. To prevent unauthorized users from changing network configuration
  2. To increase cable bandwidth
  3. To create additional VLANs automatically
  4. To disable all monitoring

Correct Answer: 1

Explanation:

Securing administrative access helps prevent unauthorized individuals from changing switch configuration or obtaining privileged information. Strong authentication, appropriate administrator permissions, secure management protocols, and restricted management access can reduce the risk of configuration tampering. Unauthorized changes can cause outages, security weaknesses, or loss of network connectivity. Administrative security does not increase physical bandwidth, automatically create VLANs, or require monitoring to be disabled. Protecting the management plane is therefore an important part of maintaining the security and reliability of a FortiSwitch deployment.

Question 179

What can an administrator use to identify whether a switch port is receiving excessive input errors?

  1. Interface statistics
  2. RADIUS accounting
  3. VLAN names
  4. LLDP system name only

Correct Answer: 1

Explanation:

Interface statistics provide detailed operational counters that can help identify problems such as input errors, packet errors, dropped packets, or other abnormal interface conditions. These counters are useful when troubleshooting faulty cables, incompatible settings, damaged interfaces, or problematic connected devices. An administrator can compare error counters over time to determine whether the problem is persistent or increasing. RADIUS accounting and VLAN names do not provide physical interface error information, while LLDP primarily provides neighbor discovery information. Therefore, interface statistics are the appropriate source for investigating excessive input errors.

Question 180

Which approach is most appropriate when multiple FortiSwitch devices require the same standardized security and interface configuration?

  1. Configure every switch independently without documentation
  2. Disable centralized management
  3. Use centralized configuration or templates where supported
  4. Remove VLAN segmentation

Correct Answer: 3

Explanation:

Centralized configuration or reusable templates can help administrators apply standardized settings across multiple FortiSwitch devices. This approach reduces repetitive manual work and helps maintain consistency between switches. Standardized configurations can include interface settings, VLAN-related parameters, security controls, and other supported policies. Administrators should still verify device-specific requirements before applying a common configuration. Independently configuring every switch increases the possibility of human error, while disabling centralized management removes useful control and visibility. Removing VLAN segmentation would also weaken network organization. Centralized configuration is therefore the most efficient approach for consistent deployments.